Re: Follow up - PHP Security problems

From: Date: Wed, 07 Nov 2001 17:34:40 +0000
Subject: Re: Follow up - PHP Security problems
References: 1 2  Groups: php.general 
Request: Send a blank email to php-general+get-73766@lists.php.net to get a copy of this message
> Instead of referencing the actual filename of the image in the source file > (from here known as "SrcFile"), reference a file (from here known as > "ImgFile") that will grab the image. Use an encryption method in the > SrcFile to create a value that corresponds to the image you want to display, > and pass that value to the ImgFile. The ImgFile will decrypt the code, grab > the appropriate image, and return the image to the SrcFile. So, instead of > seeing <img src="one.gif"><img src="two.gif"> in the SrcFile, > all you see is > <img src="ImgFile.php3?img=102342143"><img > src="ImgFile.php3?img=342014253"> > - and those "img=" values are constantly changing! > But that would still allow them to get the code. You need to NOT have a refereence to the code that was written in the image, You can have a variable that references the code in the image to a record in a DB, that would be how you would actually do the lookup to see if what they typed is the same as the one they were presented. The hacker would not have access to your DB to get the code but your PHP script would.

« previous php.general (#73766) next »